Skip to main content

Module filter

Module filter 

Source
Expand description

Classic-BPF seccomp filters built directly from the data, for the local runner: no container, no libseccomp, and no root.

The program makes the same decisions as crate::seccomp_profile:

  1. Any architecture other than x86_64 (e.g. int 0x80 i386 calls) and any x32 syscall number returns ENOSYS.
  2. madvise returns EINVAL unless the low 32 bits of the advice (the kernel reads an int) are a value the target kernel knows.
  3. Syscalls the target provides are allowed; everything else, including numbers this crate’s data does not know, returns ENOSYS.

Installing a filter needs no privilege once the process has set PR_SET_NO_NEW_PRIVS. Like the profiles, the filter is a testing aid and not a security boundary.

Modules§

install
Installs filters in the calling thread (and what it executes).

Structs§

Insn
One struct sock_filter instruction.

Constants§

AUDIT_ARCH_X86_64
AUDIT_ARCH_X86_64: EM_X86_64 | __AUDIT_ARCH_64BIT | __AUDIT_ARCH_LE.
MAX_INSNS
The kernel’s BPF_MAXINSNS.
RET_ALLOW
SECCOMP_RET_ALLOW.
RET_ERRNO
SECCOMP_RET_ERRNO; the errno goes in the low 16 bits.
SYS_MADVISE
x86_64 madvise syscall number.
X32_SYSCALL_BIT
Syscall numbers at or above this bit belong to the x32 ABI.

Functions§

evaluate
Runs prog on one syscall the way the kernel does and returns the SECCOMP_RET_* value. Supports only the opcodes program emits.
program
Builds the filter program for target.